Home SERVICES
All Services Web App Security Network Testing Cloud Security Active Directory Red Team AI Red Teaming
COMPANY
About Us Founder, Arturs Stay Certifications Why Organizations Trust CSPI FAQ
Process Partners Industries Blog Request a Quote
Back to Blog
Network Security

Network Penetration Testing: The Enterprise Guide to Internal and External Attack Paths

Every organization in Canada and the United States still runs on a network, even the ones that describe themselves as cloud-first. Domain controllers, file servers, hypervisors, backup systems, and the flat internal segments that connect them are where an attacker who gets a foothold actually does damage. The perimeter has shrunk and moved, but it has not disappeared, and the interior is where a single phished laptop becomes a domain-wide compromise. Vulnerability scanners are good at listing missing patches. They are poor at proving what an attacker reaches once they are inside, which is the question that decides how bad an incident becomes.

This guide explains what a professional network penetration test covers, how internal and external testing differ, what you receive, and how to prepare. It reflects what we find in real assessments across financial services, healthcare, manufacturing, and public-sector environments in Canada and the United States, not a generic checklist. If you want the working tool our consultants use to run these engagements, the free Network Penetration Testing Playbook is available below.

Executive takeaway: The findings that turn a minor intrusion into a major breach are rarely a single exploit. They are weak segmentation, over-trusted internal services, and reused or exposed credentials that let an attacker move laterally from one foothold to the systems that matter. A network penetration test proves which of those paths are real and how far they reach, so remediation is prioritized by demonstrated blast radius rather than by a scanner's severity label.

What Network Penetration Testing Is

Network penetration testing is a structured, authorized attempt to compromise your network infrastructure using the same techniques a real attacker would use, performed with written permission and defined rules of engagement. It covers the external perimeter that faces the internet and the internal network an attacker reaches after an initial foothold. The goal is to identify exploitable weaknesses, chain them into a validated path across the environment, demonstrate what an attacker would reach, and hand back evidence-based remediation.

It is not a vulnerability scan. A scanner enumerates missing patches and known CVEs and rates them by severity, but it cannot resolve the trust relationships between systems, prove that one compromised host reaches the domain controller, or tell a benign open port apart from the one service that unlocks the environment. That requires a skilled tester who thinks in attack paths. In our engagements, the finding that most often escalates to Critical is not a single unpatched host but a lateral-movement path the client's scanners had reported only as a list of unrelated medium-severity issues.

Network Penetration Testing vs Vulnerability Scanning, Internal, and External Testing

Network penetration testing proves exploitable attack paths across the environment with evidence, while a vulnerability scan lists known weaknesses, and the internal-versus-external distinction decides which attacker you are simulating. These terms are often used loosely, and the difference matters when you are scoping an engagement and defending the spend to a board or an auditor.

  • Vulnerability scanning finds known CVEs and missing patches on reachable hosts. It is necessary and cheap, and it is the floor, not the ceiling. It does not test trust relationships, lateral movement, or segmentation.
  • External network penetration testing simulates an attacker on the internet with no prior access, targeting the perimeter: exposed services, VPNs, and mail and web infrastructure, and the ways in that a real adversary would find first.
  • Internal network penetration testing simulates an attacker who already has a foothold, whether from a phished laptop, a rogue device, or a malicious insider, and measures how far that foothold reaches across the internal network.
  • Network penetration testing takes the weaknesses those activities surface and proves which ones chain into a real path to impact, on a defined scope and timeline. It answers the question a leader actually asks: if this were exploited, how far would the attacker get?

Most enterprises need vulnerability scanning running continuously, an external test on a defined cadence, and an internal or assumed-breach test to measure blast radius once the perimeter is reasonably hardened. For a fuller comparison, see our guide on internal versus external penetration testing.

Free download: the Network Penetration Testing Playbook

The article explains the method. The Playbook is the working toolkit our consultants run an engagement with: internal and external methodology sheets, a segmentation and lateral-movement test plan, scoping and rules-of-engagement checklists, an evidence template, and a remediation prioritization matrix. Confirm your email and we send a secure download link.

Privacy notice: Double opt-in - we email a confirmation link and the playbook downloads only after you confirm. We use your name and email to deliver the playbook and, only if you opt in above, to send marketing communications you can unsubscribe from at any time. We never sell your information. To unsubscribe or request deletion, email info@cybersecpentesting.com. See our Privacy Policy.

Educational and authorized use only. The Network Penetration Testing Playbook is provided strictly for educational and defensive security purposes. Use it only on systems you own or are explicitly authorized in writing to assess. Unauthorized access to computer systems is illegal, including under the Criminal Code of Canada (section 342.1) and the U.S. Computer Fraud and Abuse Act. You are solely responsible for how you use this material.

Why the Network Perimeter and Interior Both Matter

An attacker rarely stops at the first system they reach. The external perimeter decides how they get in, but the internal network decides how much that foothold is worth. Testing only one side answers half the question, and it is usually the less important half, because most breaches escalate on the inside. The two surfaces behave differently.

Dimension External perimeter Internal network
Attacker assumptionNo prior access, from the internetAlready has a foothold inside
Primary targetsExposed services, VPN, mail, webFile shares, credentials, Active Directory
Highest-impact flawAn exposed service or weak remote accessFlat segmentation and reused credentials
How impact is reachedBreaking in through the boundaryLateral movement to the systems that matter
What a scanner missesChained perimeter weaknessesAlmost all lateral-movement and trust risk

The External Perimeter

The external test starts where a real attacker starts: what is exposed to the internet, and what does it allow. Remote access services, VPN gateways, mail and web infrastructure, and forgotten hosts are enumerated and tested for weak authentication, missing multi-factor enforcement, and exploitable services. The perimeter is smaller than it used to be, which makes each exposed service more valuable to an attacker and more important to test properly.

The Internal Network and Assumed Breach

The internal test assumes what is now the realistic starting point: an attacker already has a foothold, from a phished user, a compromised laptop, or a device on the network. From there the tester enumerates reachable systems, harvests and reuses credentials, and measures how far the foothold extends. This assumed-breach approach reflects how modern incidents actually unfold, and it is where the most consequential findings live. A broader engagement that models the full intrusion, from initial access through objectives, is covered in our red team and adversary simulation guide.

Segmentation and Lateral Movement

Segmentation is the control that decides blast radius, and it is the one most often assumed to work and rarely proven to. A flat internal network means one compromised workstation can reach the domain controller, the backup server, and the finance systems alike. Testing segmentation means attempting the moves an attacker would make between zones, and it is where we most often turn a single foothold into environment-wide impact. Our deep-dives on network segmentation testing and internal network pivoting show how these paths are built.

The Path to Active Directory

In most enterprise networks, the internal path leads to Active Directory, because whoever controls the directory controls the environment. Credential reuse, over-privileged service accounts, and weak authentication protocols repeatedly convert a modest foothold into domain-wide control. Hybrid identity extends the same risk into the cloud, examined in our Azure and Entra ID attacks analysis and our guide to cloud penetration testing.

What a Professional Network Penetration Test Covers

A credible engagement is a structured examination of how far an attacker can move through your environment, not a scan pointed at an IP range. It runs as a repeatable sequence, and each phase feeds the next.

1 · Recon & Discovery 2 · Enumeration 3 · Exploitation 4 · Lateral Movement & Escalation 5 · Reporting & Evidence 6 · Retest

Scope and Rules of Engagement

The IP ranges, hosts, and segments in scope, whether the test is external, internal, or both, and any restrictions are named explicitly, along with the rules of engagement. Denial-of-service and disruptive testing are excluded by default. Good scoping is the first control an assessment provides, not a formality, and it aligns the engagement to your obligations, whether that is SOC 2, PCI DSS segmentation testing, HIPAA, or PIPEDA.

NIST-Based Methodology

A professional test follows a published methodology rather than a tester's memory. NIST SP 800-115, the Technical Guide to Information Security Testing and Assessment, and the Penetration Testing Execution Standard (PTES) define the phases to cover, from discovery and enumeration through exploitation, post-exploitation, and reporting. The attacker techniques used along the way are mapped to MITRE ATT&CK, so lateral movement and post-exploitation are described in a taxonomy your defenders and SOC already use. The methodology is what makes coverage repeatable and defensible to an auditor.

Manual Testing vs Automated Scanning

Tools accelerate a skilled tester and are indispensable for discovery and coverage. Nmap maps the environment and Metasploit validates exploitation. But the highest-impact outcomes, lateral movement, trust-relationship abuse, and segmentation escapes, are found by a human who chains weaknesses across systems, because they have no signature to match. An engagement that is only a tuned scanner is a scan with a higher invoice, and reviewers can tell the difference.

Automated scanner Manual penetration test
Lists missing patches and known CVEsProves lateral movement and privilege escalation
No notion of trust between systemsResolves and abuses real trust relationships
No attack chainingMulti-step paths to demonstrated blast radius
Cannot validate segmentationTests segmentation by attempting the crossing
Severity by generic labelSeverity by reach and business impact

Evidence and Finding Development

Every proven weakness is documented with reproducible evidence, tied to the systems and data it reached, and translated into business risk. Findings are prioritized by validated blast radius, not by a scanner's default severity. The engagement also records what could not be confirmed, so a limitation reduces confidence in coverage rather than being mistaken for an absence of risk.

Common Network Attack Paths We Prove

Across Canadian and U.S. engagements, a handful of paths recur, and naming them helps security teams recognize their own exposure. These are the chains we most frequently develop from a foothold to demonstrated impact:

  • External foothold to internal access: a weak remote-access service or exposed web application on the perimeter provides the first step onto the internal network.
  • Assumed breach to domain admin: from a single internal foothold, credential harvesting and reuse escalate to control of Active Directory and the wider environment.
  • Segmentation escape: a flat or weakly segmented network lets one compromised host reach systems that were assumed to be isolated, including the backup and finance environments.
  • Credential reuse across zones: a shared local administrator password or an over-privileged service account bridges systems that should have been separated.

What We Actually Test in a Network

Scope is agreed per engagement, but a full network penetration test typically covers the areas below, with depth prioritized by where your environment actually carries risk.

External Perimeter Internal Network Firewall & VLAN Segmentation Lateral Movement Privilege Escalation Active Directory Credential Attacks Service Enumeration Patch & Configuration Man-in-the-Middle & Relaying VPN & Remote Access Network Devices Wireless (in scope) Multi-Step Attack Chains

How Findings Become Business Risk

A finding is only useful when it is expressed as risk a leader can act on. The severity of a network issue is decided less by the sophistication of the exploit than by the reach it provides. The same missing patch is a minor issue on an isolated host and a critical one on a system that bridges into the domain, and a good report makes that distinction explicit by measuring blast radius rather than counting vulnerabilities.

A professional report separates technical impact from business translation and maps findings to the frameworks your organization answers to. NIST CSF 2.0 and CIS Controls v8 provide the control language; SOC 2, PCI DSS, and HIPAA drive audit expectations in the US; and PIPEDA, under the Office of the Privacy Commissioner, sets the reasonable-safeguard expectation in Canada, addressed in our PIPEDA penetration testing guide. PCI DSS in particular requires segmentation penetration testing (requirement 11.4.5), which only a network penetration test provides. A vulnerability scan report does not satisfy these frameworks where human-led testing is expected, and reviewers know the difference.

Key takeaway: Presenting a vulnerability scan export to a SOC 2, PCI DSS, or HIPAA reviewer as your penetration test evidence is a compliance gap. PCI DSS explicitly requires segmentation penetration testing, and these frameworks expect human-led exploitation that proves reachability and blast radius, not an automated list of missing patches.

What to Expect From a Network Penetration Testing Engagement

Buyers ask the same practical questions before commissioning a test. Here is what a CSPI network engagement involves, so there are no surprises when you scope one.

Who performs the testingA named principal consultant (CREST CRPT, OSCP, OSEP), not an outsourced or rotating team. The person who tests writes the report.
Access requiredFor external testing, the in-scope IP ranges. For internal testing, network access (an on-site connection, a shipped device, or a VPN) and, for assumed-breach, a standard user account and endpoint.
Production impactTesting is deliberately non-destructive. Denial-of-service is excluded, exploitation is validated carefully, and intrusive checks are scheduled around change windows.
TimelineA focused external or internal engagement typically takes one to two weeks of testing plus reporting; a large estate with segmentation testing extends it. The scoping call sets the schedule.
How findings are validatedEvery finding is manually proven and captured with reproducible evidence. Scanner output is triaged and confirmed before it appears in the report, so there are no unverified false positives.
What you receiveA technical report with reproducible evidence, an executive summary, business-risk translation, prioritized remediation, framework mapping, and a retest of fixed findings.
Included vs excludedScope is fixed in writing: named ranges, segments, and test type in scope; denial-of-service, physical intrusion, and third-party-hosted systems out of scope unless explicitly agreed.

How to Prepare for a Network Penetration Test

A few steps make the engagement faster and more valuable. Confirm the in-scope ranges and the test type (external, internal, or both) and arrange the network access the internal test needs before the start date. Provide an assumed-breach user account and endpoint if that scenario is in scope, and confirm in writing how any sensitive data will be handled. Share a network diagram and any known areas of concern, so the tester spends time on depth rather than rediscovery. Confirm authorization and rules of engagement, and agree in advance how findings will be prioritized and retested, so the report drives action rather than sitting in an inbox. For where a network test fits alongside application testing, see what penetration testing is and what penetration testing costs in Canada.

What You'll Receive in the Network Penetration Testing Playbook

The article explains the method. The Playbook is the actionable toolkit that lets you run or govern an engagement, and it complements the guide rather than repeating it. It is a working document, not a marketing brochure, and it includes:

  • A scoping worksheet to define ranges, segments, test type, and success criteria before a single packet is sent.
  • A rules-of-engagement checklist covering authorization, exclusions, data handling, testing windows, and communication.
  • Internal and external methodology sheets aligned to NIST SP 800-115, covering discovery, enumeration, exploitation, and post-exploitation.
  • A segmentation and lateral-movement test plan for proving what an attacker reaches between zones, where the highest-impact findings appear.
  • An evidence collection template so each finding is captured reproducibly, and a findings register that scores severity by blast radius.
  • A remediation prioritization matrix and an executive reporting checklist so fixes are sequenced by risk and the results land with leadership, plus a fully sanitized worked example (assumed breach to domain admin).
Get the playbook: Use the download form above to receive your secure copy. Planning an actual engagement? Our network penetration testing service scopes external and internal environments for enterprises in Canada and the United States.

Frequently Asked Questions

What is network penetration testing?

Network penetration testing is an authorized, human-led assessment that emulates a real attacker against your network infrastructure, external and internal. Rather than only listing missing patches, a tester enumerates services and trust relationships, chains weaknesses into a validated path across the environment, demonstrates how far an attacker reaches, and documents evidence and prioritized remediation.

What is the difference between internal and external network penetration testing?

External testing simulates an attacker on the internet with no access, targeting the perimeter: exposed services, VPNs, and remote access. Internal testing simulates an attacker who already has a foothold, from a phished laptop or rogue device, and measures how far that foothold reaches through the internal network. Most enterprises need both.

What are the stages of a network penetration test?

A professional network penetration test runs as a repeatable sequence: scoping and rules of engagement, reconnaissance and enumeration, exploitation, lateral movement and privilege escalation, and reporting with evidence, business-risk translation, and retest. The methodology, aligned to NIST SP 800-115 and PTES, matters more than any single tool.

Which tools are used for network penetration testing?

Nmap for discovery and service enumeration and Metasploit for validated exploitation are common, alongside targeted tooling for credential attacks, relaying, and Active Directory analysis. Tools accelerate a skilled tester, but segmentation weaknesses, trust-relationship abuse, and lateral-movement paths are proven by a human, not a scanner.

How much does network penetration testing cost?

Cost depends on scope: the number of live hosts and IP ranges, whether the engagement is external, internal, or both, the size of the internal estate, and whether segmentation testing is included. Most enterprise network penetration tests in Canada and the US are scoped as a fixed-price engagement after a short scoping call, with pricing set before work begins.

How long does a network penetration test take?

A focused external or internal engagement typically runs one to two weeks of testing plus reporting; a large internal estate with segmentation testing takes longer. The scoping call establishes a realistic timeline before the engagement starts.

Will a network penetration test affect our production systems?

Testing is deliberately non-destructive. Denial-of-service and disruptive checks are excluded by default, exploitation is validated carefully, and any potentially intrusive activity against production is agreed in advance and scheduled around change windows so availability is protected while the test still reflects real risk.

Does network penetration testing support SOC 2, PCI DSS, HIPAA, or PIPEDA compliance?

Yes. Human-led network penetration testing produces the exploitation evidence that SOC 2, PCI DSS, HIPAA, and PIPEDA reviewers expect, including PCI DSS segmentation testing, and maps to NIST CSF 2.0 and CIS Controls v8. A vulnerability scan report alone does not satisfy these frameworks where testing of real, exploitable risk is expected.

Network security is won or lost in segmentation, credentials, and the paths between systems. As a network penetration testing company serving enterprises in Canada and the United States, we prove, with evidence, how far an attacker could actually move. Start with the playbook above, then talk to us about a scoped internal or external network penetration testing engagement.

RELATED ARTICLES
Explore Network Penetration Testing Services →